HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Farmer Brothers Company
bd_ff0874b846405f0e · schema v1 · pii pii-v1
Full breach record for Farmer Brothers Company →Farmer Brothers Company notified the New Hampshire Attorney General of a data event affecting 14 NH residents. Unauthorized access to archived files occurred between March 6 and March 14, 2025. The actor accessed names, SSNs, and driver's license numbers. Farmer Brothers reported to federal law enforcement, implemented safeguards, and provided 12 months of credit monitoring via TransUnion to affected individuals.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_2346ff290be14cdbVermont State AGfiled 2025-09-09Verified
- bd_4bcd2385a0817f7dOregon State AGfiled 2025-09-09Candidate
- bd_557b222edc9b4bbdCalifornia State AGfiled 2025-09-09Verified
- bd_a19ba8de6f2b3f9bMaine State AGfiled 2025-09-09Verified by operator
Show 4 more filings ↓Show fewer ↑up to 1d gap
- bd_bf5d5f7c554e3c44Montana State AGfiled 2025-09-09Verified by operator
- bd_d19f1c0203deb124Indiana State AGfiled 2025-09-09Verified
- bd_611ab6b8e533b454Washington State AGfiled 2025-09-10(1d gap)Verified by operator
- bd_6975b4edc70a9985Texas State AGfiled 2025-09-10(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/farmer-brothers-20250909.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 9, 2025
- Raw hash
- 0f7af82dc398c668645d31f1aaab6d6167aa0b75e2207509e67a95dbe42a608a
Reporting entity
- Name
- Farmer Brothers Companynorm: farmer brothers
- Domain
- farmerbros.com
Victim entity
- Name
- Farmer Brothers Companynorm: farmer brothers
- Domain
- farmerbros.com
Incident
- Discovered
- Mar 14, 2025
- Materiality determined
- —
- Notification sent
- Sep 9, 2025
- Affected individuals
- 14
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- reported this event to federal law enforcement
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(179 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.